Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,990
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 1,841 - 1,860 of 3,443 CVEs
CVE-2026-34159 CRITICAL - 9.8

llama.cpp is an inference of several LLM models in C/C++. Prior to version b8492, the RPC backend's deserialize_tensor() skips all bounds validation when a tensor's buffer field is 0. An unauthenticated attacker can read and write arbitrary process memory via crafted GRAPH_COMPUTE messages...

Vendor: ggml-org
Product: llama.cpp
Published: Apr 01, 2026
Source: NVD
CVE-2026-30643 CRITICAL - 9.8

An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload.

Vendor: dedecms
Product: dedecms
Published: Apr 01, 2026
Source: NVD
CVE-2026-20160 CRITICAL - 9.8

A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host. This vulnerability is due to the unintentional exposure of an internal s...

Vendor: Cisco
Product: Cisco Smart Software Manager On-Prem
Published: Apr 01, 2026
Source: NVD
CVE-2026-20093 CRITICAL - 9.8

A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin. This vulnerability is due to incorrect handling of password change request...

Vendor: Cisco
Product: Cisco Enterprise NFV Infrastructure Software, Cisco Unified Computing System (Standalone), Cisco Unified Computing System E-Series Software (UCSE)
Published: Apr 01, 2026
Source: NVD
CVE-2024-43028 CRITICAL - 9.8

A command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3 allows attackers to execute arbitrary code via a crafted HTTP request.

Vendor: jeecg
Product: jeecg_boot
Published: Apr 01, 2026
Source: NVD
CVE-2024-40489 CRITICAL - 9.8

There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attackers to execute arbitrary code on components through specially crafted HTTP requests.

Vendor: jeecg
Product: jeecg_boot
Published: Apr 01, 2026
Source: NVD
CVE-2026-31027 CRITICAL - 9.8

TOTOlink A3600R v5.9c.4959 contains a buffer overflow vulnerability in the setAppEasyWizardConfig interface of /lib/cste_modules/app.so. The vulnerability occurs because the rootSsid parameter is not properly validated for length, allowing remote attackers to trigger a buffer overflow, potentially l...

Vendor: totolink
Product: a3600r_firmware
Published: Apr 01, 2026
Source: NVD
CVE-2026-29014 CRITICAL - 9.8

MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can exploit insufficient input neutralization in the execution path to achieve remo...

Vendor: MetInfo CMS
Product: MetInfo CMS
Published: Apr 01, 2026
Source: NVD
CVE-2026-4370 CRITICAL - 10.0

A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the internal Dqlite database cluster fails to perform proper TLS client and server authentication. Specifically, the Juju controller's database endpoint does not validate client certif...

Vendor: go
Product: github.com/juju/juju
Published: Apr 01, 2026
Source: NVD
CVE-2025-15484 CRITICAL - 9.1

The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant full access to all unauthenticated requests, enabling complete read/write access to store resources like products, coupons, and customers.

Vendor: Unknown
Product: Order Notification for WooCommerce
Published: Apr 01, 2026
Source: NVD
CVE-2026-5290 CRITICAL - 9.6

Use after free in Compositing in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: Apr 01, 2026
Source: NVD
CVE-2026-5289 CRITICAL - 9.6

Use after free in Navigation in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: Apr 01, 2026
Source: NVD
CVE-2026-5288 CRITICAL - 9.6

Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: Apr 01, 2026
Source: NVD
CVE-2025-71279 CRITICAL - 9.8

XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the security of Passkey-based authentication.

Vendor: XenForo
Product: XenForo
Published: Apr 01, 2026
Source: NVD

FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The RequestDirector class is responsible for constructing HTTP requests to the backend service. A vulnerability e...

Vendor: pip
Product: fastmcp
Published: Mar 31, 2026
Source: GitHub
CVE-2026-34449 CRITICAL - 9.6

SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can achieve Remote Code Execution (RCE) on any desktop running SiYuan by exploiting the permissive CORS policy (Access-Control-Allow-Origin: * + Access-Control-Allow-Private-Network: true) to inject a JavaS...

Vendor: siyuan-note
Product: siyuan
Published: Mar 31, 2026
Source: NVD
CVE-2026-34448 CRITICAL - 9.0

SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field can trigger stored XSS when a victim opens the Gallery or Kanban view with β€œCover From -> Asset Field” enabled. The vulnerable code accepts arbitrar...

Vendor: siyuan-note
Product: siyuan
Published: Mar 31, 2026
Source: NVD
CVE-2026-1579 CRITICAL - 9.8

The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message signing is not enabled, any message -- including SERIAL_CONTROL, which provides interactive shell access -- can be sent by an unauthenticated party with access to the MAVLink int...

Vendor: px4
Product: autopilot
Published: Mar 31, 2026
Source: NVD
CVE-2026-30285 CRITICAL - 9.8

An arbitrary file overwrite vulnerability in Zora: Post, Trade, Earn Crypto v2.60.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

Vendor: zora
Product: zora
Published: Mar 31, 2026
Source: NVD
CVE-2026-30286 CRITICAL - 9.8

An arbitrary file overwrite vulnerability in Funambol, Inc. Zefiro Cloud v32.0.2026011614 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

Vendor: funambol
Product: zefiro
Published: Mar 31, 2026
Source: NVD